Security

Last updated: September 24, 2026

Reporting a security problem

If you think you have found a vulnerability in JobLoad360, email privacysecurity@jobload360.com. Include what you found, where, and the steps to reproduce it. We confirm we have it within five business days and keep you told what we are doing about it.

We will not pursue anyone who researches in good faith and within these limits: use only your own accounts and data; stop and tell us as soon as you reach another company's data, and do not keep, share, or change it; do nothing that degrades the service for others (no load testing, spam, or social engineering of our users or staff); and give us a reasonable time, 90 days by default, to fix a problem before you publish it. We do not run a paid bug bounty.

The same contact is published in machine-readable form at /.well-known/security.txt.

Where your data lives

JobLoad360 is operated by R31 Holdings LLC. The app and its data are hosted by Base44, whose security documentation states that data is encrypted at rest and in transit, that Base44 is SOC 2 Type II and ISO 27001 certified, and that it is penetration-tested regularly by internal and third-party teams. Traffic reaches it through Cloudflare.

We are moving JobLoad360 onto servers we run ourselves, with encrypted, point-in-time-recoverable backups whose restore we test. That move happens one part of the app at a time, and customer data stays with Base44 until its part moves. This page will say when it does.

Encryption in transit

Every page and every request is served over HTTPS only, and browsers are told never to connect over plain HTTP (HTTP Strict Transport Security).

Company isolation and access control

  • Every company's records carry that company's id, and every read and write compares it with the signed-in user's company. Being a manager never replaces that check: access needs the right role and the right company.
  • Money, signed documents, the activity log, and other sensitive records cannot be written from the browser at all. Those changes go through server functions that work out the company from the signed-in user, never from what the browser sends.
  • Crew permissions for sensitive features start switched off until a manager grants them.
  • Quote, invoice, and customer portal links use long random tokens that a company can revoke, and portal links expire. A customer sees only what the company chose to share, and job photos stay private unless someone marks them customer-visible.

Payments

Card payments, for subscriptions and for customers paying a company's invoice, are taken on Stripe's own checkout pages. Card numbers go straight to Stripe, a PCI DSS Level 1 service provider, and never reach JobLoad360.

Records you can rely on

A signed quote, invoice, or change order is kept as a sealed copy with a SHA-256 integrity hash, for a minimum period the company sets: seven years from signing unless it chooses another. Payment adjustments cannot be edited once made, and the activity log can only be added to.

Signing in

Passwords are held by Base44's sign-in service; JobLoad360 never sees or stores them. A new or reset password must be at least 12 characters and is checked against passwords exposed in known data breaches. The check sends only the first five characters of the password's SHA-1 hash, never the password. When a session is rejected, the app discards its stored sign-in token.

Two-factor sign-in. Anyone can add an authenticator app code (TOTP) to their password under My Profile, with recovery codes for a lost phone. A company owner can require it of everyone in the company, and managers of Pro companies are required to use it from December 23, 2026. Five wrong codes lock the second factor for fifteen minutes. Authenticator secrets are stored encrypted.

What it covers today: opening the app, and every action that reaches money, the books, or an export (connecting Stripe, QuickBooks, Xero or Google Drive, exporting to Excel or payroll, and deleting the company's data) refuses a session that has not confirmed a code within the last twelve hours, even when called outside the app. Until sign-in itself moves to our own servers (above), plain reads of records under a stolen password are not covered by the second factor.

Protections in your browser

Pages are sent with headers that stop other sites from framing JobLoad360 and stop browsers from guessing file types, a referrer policy that keeps page addresses from leaking to other sites, and a Content-Security-Policy that blocks plugins, stops the page's base address from being changed, and keeps forms from posting anywhere but JobLoad360.

If something goes wrong

We investigate every reported problem, contain it, and fix it. If a breach affects a company's data, we tell that company without undue delay, with what happened, what data was involved, and what we are doing, and we meet the notice requirements of US breach-notification laws.

Service providers

The providers that receive personal information to run JobLoad360, and what each one gets. The Privacy Policy explains how we use it and how long we keep it.

  • Base44

    Hosts the app and stores its data: accounts and sign-in, every record, uploaded photos, videos and documents, and the email the app sends.

    Receives: All account, company, and customer data

  • AI model providers, through Base44

    Draft scopes, walkthrough logs, change-order and scope-change summaries, blueprint takeoffs, and material price searches. The request carries what the feature is working from: notes, and for field scopes and takeoffs the photos, voice notes, or drawings. Base44 chooses the provider; some features use Google's Gemini models.

    Receives: The text, photos, voice notes, and drawings a feature is asked to work on

  • Stripe

    Subscription billing, and card payments customers make on a company's invoices. Card numbers go to Stripe directly and never reach JobLoad360.

    Receives: Names, email addresses, billing details, payment records

  • HeyCatch

    Product analytics: which screens are used and where the app breaks. For a signed-in user it receives the user id, name, and email address.

    Receives: Usage events, device and browser details, user id, name, email

  • US Census Bureau Geocoder, Photon (Komoot), and OpenStreetMap Nominatim

    Turn a job's address into map coordinates for the job map.

    Receives: Job site addresses

  • OpenStreetMap

    Map tiles for the job map, loaded by your browser.

    Receives: Your IP address and the area of the map you view

  • Google Fonts

    The site's typefaces, loaded by your browser.

    Receives: Your IP address

  • Intuit QuickBooks and XeroOnly if a company connects it

    Accounting sync, when a company connects one.

    Receives: Customers, invoices, and payments the company syncs

  • Microsoft (Excel and OneDrive)Only if a company connects it

    Excel export to the company's own OneDrive, when a Pro company connects it.

    Receives: The records the company exports

Privacy Policy·Security·Terms·License·Home